Cambridge University Library

https://www.lib.cam.ac.uk · 46/92 checks passed · libraries

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 26/37 (11 failed)
Level 2 — Enhanced 8/27 (19 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 8/13
Accountability 0/5
AI & Automation 3/8
Interoperability 1/3
Privacy 10/16
Provenance 1/2
Security 5/11
Transparency 6/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page contains no AI use policy or statement in its content or footer links.
    Fix: Publish an AI use policy page and link to it from the site footer or About section.
  • scope_clear: There is no mention of AI usage, so the scope of AI use is not explained.
    Fix: Add a clear statement describing what AI tools are used for on the site (e.g., search, content generation, translation).

Privacy

Security

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists only generic contacts (library@lib.cam.ac.uk, stories@lib.cam.ac.uk) without naming any specific person or role responsible.
    Fix: Add the name or job title of the person or team (e.g., Head of Communications, Library Director) responsible for each enquiry category.
  • response_timeframe: The contact page lists phone, email, and address but does not state any timeframe for when enquiries will receive a response.
    Fix: Add a statement near the contact details indicating expected response times (e.g., 'We aim to respond within 5 working days').
  • specific: Since no response timeframe is published at all, there is no specific duration given.
    Fix: Publish a concrete, specific timeframe in days or working days for replies to general, media, and comments enquiries.
  • process_exists: The page only refers vaguely to a 'Comments Form' for suggestions and does not document a complaints or feedback process.
    Fix: Publish a dedicated complaints/feedback procedure explaining how complaints are received, handled, escalated, and resolved.
  • steps_clear: No step-by-step guidance is provided for submitting a complaint beyond a link to a generic comments form.
    Fix: Add numbered steps describing how to submit a complaint, what information to include, who reviews it, and how outcomes are communicated.
  • appeals_exists: The contact page only lists general enquiry emails, phone, address, and a comments form, with no documented appeals process described.
    Fix: Add a clearly labeled appeals procedure describing how users can formally challenge decisions, including steps, timelines, and contact points.
  • independent: No escalation path or independent reviewer is identified; all contact routes lead back to the Library itself.
    Fix: Specify an independent or higher-level escalation route (e.g., University ombudsman or an external reviewer) for unresolved appeals.

AI & Automation

  • detailed_scope: No AI policy is present on this page, so scope of AI use is not detailed.
    Fix: Create an AI policy that specifies which systems, use cases, and data are covered by AI usage.
  • limitations: No limitations of AI systems are acknowledged since no AI policy appears on the page.
    Fix: Include an AI limitations section noting issues such as inaccuracies, bias, and appropriate contexts for use.
  • safeguards: No safeguards or quality controls for AI are described on the page.
    Fix: Describe safeguards such as human review, accuracy checks, and governance processes applied to AI outputs.
  • marking_policy: The About page contains no policy or statement about marking AI-assisted content.
    Fix: Publish a clear policy describing how AI-assisted content is labeled on the site and link to it from the About or policies section.
  • consistent: No AI content markings are visible on the page, so consistent application cannot be demonstrated.
    Fix: Adopt a uniform labeling convention (e.g., an 'AI-assisted' tag) and apply it to every page or section where AI is used.
  • oversight_exists: The page does not mention any human oversight process for AI outputs.
    Fix: Add documentation describing how staff review and supervise AI-generated outputs before publication.
  • review_process: No review or approval workflow for AI content is described anywhere on the page.
    Fix: Document the editorial review/approval steps AI-assisted content must pass through and publish them in a governance or policy page.
  • accountability: No individual, role, or office is identified as accountable for AI-generated content.
    Fix: Name a responsible role or office (e.g., a designated editor or AI governance lead) and list their contact details in the About or governance pages.

Interoperability

Privacy

  • necessity: The policy does not explicitly state that data collection is limited to the minimum necessary / data minimisation principle.
    Fix: Add an explicit statement that the Library only collects personal data that is necessary for the stated purposes (data minimisation).
  • retention_stated: The page does not state any data retention periods, only linking to a general University data protection page.
    Fix: Add a dedicated retention section stating how long each category of personal data (e.g., reader registration, ILL requests, event attendance) is kept.
  • specific: Because no retention periods are provided on the page, there are no specific timeframes given.
    Fix: Specify concrete retention durations (e.g., '3 years after account closure') for each data category rather than omitting or using vague language.
  • equal_choices: The page offers no in-page accept/reject controls, instead directing users to disable cookies via browser settings, which does not present equally prominent choices.
    Fix: Implement a consent banner with clearly visible and equally prominent 'Accept' and 'Reject' buttons for non-essential cookies.
  • no_forced_consent: Statistics cookies appear to be used without an explicit opt-in mechanism described on the page, effectively bundling them with essential cookies.
    Fix: Separate essential from statistics cookies and require explicit opt-in consent for non-essential cookies before they are set.
  • banner_present: No cookie or consent banner content is visible on the page; only a footer link to 'Privacy and Cookie Policy' appears.
    Fix: Implement a visible cookie consent banner on first visit that allows users to accept or reject cookies.
  • partner_sharing_mentioned: The page contains no on-page consent copy disclosing data sharing with third-party partners.
    Fix: Add clear disclosure within the cookie banner describing which third-party partners receive user data and for what purposes.
  • partner_count_specific: No numeric count of partners is stated anywhere on the page since no partner sharing is disclosed.
    Fix: Include a specific count of third-party partners (e.g., 'We share data with X partners') in the consent banner along with a link to the full list.

Provenance

Security

Transparency

  • named_person: No named individual or specific team is identified; only generic departmental email aliases are provided.
    Fix: Identify the team or individual (e.g., 'Press Office', 'Enquiries Team lead') behind each email alias so users know who handles their enquiry.
  • role_clear: While enquiry categories (general, media, comments) are labelled, no role or authority of the responder is stated.
    Fix: Clarify the role and remit of the responder for each channel, e.g., 'Media enquiries handled by the Library Press Officer'.
  • detail: The About page itself provides no amounts, percentages, or categories of funding—only links to reports where such detail may live.
    Fix: Add a brief summary on the About page with key funding figures or category breakdowns (e.g., tuition, research grants, endowment) alongside the link to full financial statements.
  • complete: The page does not enumerate major funding streams such as research grants, tuition, donations, or government funding on the page itself.
    Fix: Include a concise list of all major funding streams (research income, tuition, endowment, philanthropic gifts, government funding) on the About page or a dedicated funding summary section.
  • roles_clear: While the page references 'People', 'Governance', and 'Processes' sections, it does not identify specific key roles or responsibilities within the editorial or governance structure on this page itself.
    Fix: Add a brief summary on this About page listing key governance roles (e.g., Vice-Chancellor, Council, Regent House) with their responsibilities, or link directly to a roles-and-responsibilities page.
  • algorithm_explained: The About page contains no mention of algorithms or automated decision-making systems or their purpose.
    Fix: Add a section (or link to a dedicated page) describing any algorithms used by the University and their intended purpose.
  • impact_clear: There is no description of how algorithmic decisions affect students, staff, or the public on this page.
    Fix: Include a clear explanation of how any algorithmic decisions impact users, such as admissions, research allocation, or service delivery.
  • annual_statement: The page links to a privacy policy and annual reports but shows no evidence of a regular or periodic review of data practices.
    Fix: Add a note to the privacy policy (linked from the footer) stating when it was last reviewed and committing to a periodic (e.g., annual) review cadence.
  • dated: Neither the footer privacy link nor any visible data practices statement on this page shows a date or version indicator.
    Fix: Include a 'Last updated' date or version number on the privacy policy and reference it where data practices are mentioned.

Level 3 — Advanced

Accessibility

  • statement_exists: This page is a service-oriented guide about accessibility support for disabled library users, not a formal accessibility statement about the website's conformance.
    Fix: Publish a dedicated accessibility statement describing the website's conformance with WCAG/regulatory standards, ideally linked from the footer 'Accessibility' link.
  • known_issues: The page describes services and facilities but does not acknowledge any known accessibility issues or limitations of the website or services.
    Fix: Add a section listing known accessibility barriers and any content that is not yet fully accessible.
  • remediation_timeline: There is no timeline or commitment for fixing accessibility issues, only general turnaround times for alternate format requests.
    Fix: Include target dates or a commitment schedule for remediating identified accessibility issues.
  • feedback_channel: Contact emails (disability@lib.cam.ac.uk, library@lib.cam.ac.uk) are provided, but there is no stated commitment to respond within a defined timeframe.
    Fix: Add a clear feedback mechanism for accessibility problems with an explicit response-time commitment (e.g., 'we aim to respond within 5 working days').

Accountability

  • enforcement: While the page states the University reserves the right to review, edit or remove contributions, it does not explain the enforcement process such as how violations are reported, reviewed, or appealed.
    Fix: Add a section describing the enforcement workflow, including how users can report violations, how the University reviews contributions, expected response times, and any appeal or reinstatement process.

Interoperability

Security

  • plan_exists: The page is an 'About the University' overview and contains no published incident response plan or security policy.
    Fix: Publish an incident response plan or security policy and link to it from the site's footer or relevant governance pages.
  • notification_commitment: The page makes no commitment to publicly notify users about significant security incidents.
    Fix: Add an explicit statement committing to public notification of significant incidents within the incident response policy.
  • timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., notifying affected users within 72 hours of detection) in the incident response documentation.

Transparency

  • criteria_published: No specific criteria for any algorithmic decision-making are published on this page.
    Fix: Publish the specific criteria used in any algorithmic decision processes, either directly or via a linked transparency page.
  • weighting: The page does not explain the weighting or prioritisation of any decision criteria.
    Fix: Document the relative weights or priority order applied to each criterion in algorithmic decisions.
  • auditable: No technical detail, documentation, or audit mechanism is provided that would enable external review.
    Fix: Provide auditable documentation (e.g., model cards, methodology reports, or an independent audit summary) accessible from the About section.
  • open_source: The page contains no links to source code repositories or open-source projects for the site.
    Fix: Add a link to a public repository (e.g., GitHub) for the site's source code or clearly state the site's licensing/open-source status.
  • tech_docs: No technical documentation about the site's platform, APIs, or data is referenced on the page.
    Fix: Publish and link to technical documentation (e.g., API docs, data schemas, or a developers page) from the About section.

Responsibility to the Future

  • disclosure_exists: The page lists sections like history, term dates, and annual reports but contains no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated environmental or sustainability disclosure page and link it from the About the University section.
  • specific_metrics: No specific figures for carbon, energy use, or emissions appear anywhere on the page.
    Fix: Include measurable metrics such as annual carbon emissions, energy consumption, and reduction targets in the sustainability disclosure.
  • hosting_disclosure: The page provides no information about the carbon or energy profile of its hosting infrastructure.
    Fix: Add a statement disclosing the hosting provider's energy source or carbon footprint, ideally referencing green hosting credentials.
  • plan_exists: The About page describes the University's structure, mission, and history but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a continuity or succession plan describing how services and operations would be maintained or wound down in the event of organisational failure or exit.
  • data_and_content_fate: The page and its footer links (privacy policy, terms) address current operations but say nothing about the fate of user data and published content if the organisation ceases to exist.
    Fix: Add a statement clarifying how user data and published content would be preserved, transferred, or deleted should the organisation shut down.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page for safeguarding content after an exit.
    Fix: Name a designated custodian, archive partner, or mirroring arrangement (e.g., a national web archive) responsible for preserving the site's content.
  • policy_exists: The page is an 'About the University' overview and contains no published policy on worker wellbeing or working conditions, only a Modern Slavery statement link unrelated to internal staff wellbeing.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the About or a Staff/HR section of the site.
  • specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere in the page content.
    Fix: Add explicit, measurable commitments covering pay, working hours, mental health support, and staff benefits to a published policy.
  • accountability: The page does not identify any named person, committee, or oversight body responsible for worker conditions.
    Fix: State who is accountable for worker wellbeing (e.g., an HR director or oversight committee) and describe the review/reporting mechanism.